Security News > 2021 > February > Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores

Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores
2021-02-11 21:32

With Valentine's Day approaching this weekend, several people have received "Recent order" email confirmations for flowers or lingerie.

These emails are actually part of a spear-phishing attack, which ultimately leads recipients to a malicious document that executes the BazaLoader malware.

Recently, researchers found multiple BazaLoader campaigns in January and February, which have relied heavily on human interaction with different sites, PDF attachments and email lures.

"There were a range of lure and subject topics, including compact storage devices, office supplies, pharmaceutical supplies and sports nutrition, but what stuck out were campaigns that were timely and relevant to the upcoming Valentine's Day holiday," said researchers with Proofpoint on Thursday.

While researchers did not specify what malware gets loaded after this first-stage infection, BazaLoader has been noted for its code similarity to TrickBot, and has been associated with Ryuk ransomware infections.

The most recent Valentine's Day attack notably reflects an attack vector with an increase on human interaction.


News URL

https://threatpost.com/valentines-day-malware-attack/163900/